CVE-2026-78047

A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user.

  • Published Aug 28, 2026
  • CVSS 5.1 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78047 at the National Vulnerability Database